Skip to content

deps(deps): bump the minor-and-patch group across 1 directory with 6 updates - #233

Merged
Divkix merged 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-fef86e2dea
Sep 28, 2026
Merged

Divkix merged 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-fef86e2dea

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 6 updates in the / directory:

Package From To
@lucide/svelte 1.47.0 1.48.0
better-auth 1.7.5 1.7.6
bits-ui 2.19.2 2.19.3
knip 6.37.0 6.38.0
@size-limit/preset-small-lib 14.0.0 14.0.1
size-limit 14.0.0 14.0.1

Updates @lucide/svelte from 1.47.0 to 1.48.0

Release notes

Sourced from @​lucide/svelte's releases.

Version 1.48.0

What's Changed

New Contributors

Full Changelog: lucide-icons/lucide@1.47.0...1.48.0

Commits

Updates better-auth from 1.7.5 to 1.7.6

Release notes

Sourced from better-auth's releases.

v1.7.6

better-auth

Features

  • Added support for a bannedUserMessage function that receives the banned user, allowing sign-in errors to include details such as the ban reason. (#11325)
  • Added Vercel BotID as a captcha provider for protected authentication routes. (#11016)

Bug Fixes

  • Passwords over maxPasswordLength are now rejected with PASSWORD_TOO_LONG before hashing or verification. (#11324)
  • Fixed React hydration mismatches when session or plugin auth queries resolve before streamed components hydrate. (#11316)
  • Prevented older auth-query responses from overwriting newer results when requests overlap. (#11376)
  • Fixed model identity when a custom model name matches another schema key. (#11333)
  • Fixed schema validation for Cloudflare D1 when the Kysely dialect cannot introspect the database. (#11366)
  • Fixed social account linking through the OAuth Proxy plugin. (#11268)

For detailed changes, see CHANGELOG

@better-auth/kysely-adapter

Bug Fixes

  • Fixed model identity when a custom model name matches another schema key. (#11333)
  • Fixed schema validation for SQLite-generated primary keys, including INTEGER PRIMARY KEY columns without AUTOINCREMENT. (#11374)
  • Fixed schema validation for Cloudflare D1 when the Kysely dialect cannot introspect the database. (#11366)

For detailed changes, see CHANGELOG

@better-auth/prisma-adapter

Bug Fixes

  • Fixed model identity when a custom model name matches another schema key. (#11333)
  • Fixed schema validation for capitalized custom Prisma model names. (#11319)

For detailed changes, see CHANGELOG

@better-auth/core

Bug Fixes

  • Fixed model identity when a custom model name matches another schema key. (#11333)

For detailed changes, see CHANGELOG

@better-auth/drizzle-adapter

Bug Fixes

... (truncated)

Changelog

Sourced from better-auth's changelog.

1.7.6

Patch Changes

  • #11325 af88385 Thanks @​Wadiou! - Admin plugin bannedUserMessage can now be a function that receives the banned user, so sign-in errors can include details such as the ban reason.

  • #11268 2fa501c Thanks @​bytaesu! - Support linking social accounts through the OAuth Proxy plugin.

  • #11366 d41e2ca Thanks @​bytaesu! - Use targeted PRAGMA queries when a Kysely dialect cannot introspect Cloudflare D1.

  • #11016 3d0efa3 Thanks @​davbrito! - Support Vercel BotID checks on protected authentication routes in Vercel-hosted applications.

  • #11333 631ac29 Thanks @​bytaesu! - Preserve logical model identity when a custom model name matches another schema key.

  • #11324 8853419 Thanks @​XXMOHAMED012! - Passwords longer than maxPasswordLength are now rejected with PASSWORD_TOO_LONG before hashing on sign-in (email, username, phone number), verify-password, change-password (currentPassword), delete-user, the two-factor endpoints that take a password, and admin create-user, matching what sign-up and password reset already did.

  • #11316 2ee1545 Thanks @​Smidge! - Fix React hydration mismatches when a session or plugin auth query resolves before a streamed component hydrates. Preserve the server-rendered pending state during hydration, then update to the current client state without changing ordinary or computed plugin stores.

  • #11376 fc45d08 Thanks @​bytaesu! - Prevent older auth-query responses from replacing newer results when requests overlap.

  • Updated dependencies [41b7dc1, d41e2ca, 631ac29, 2b13e01]:

    • @​better-auth/prisma-adapter@​1.7.6
    • @​better-auth/kysely-adapter@​1.7.6
    • @​better-auth/core@​1.7.6
    • @​better-auth/drizzle-adapter@​1.7.6
    • @​better-auth/memory-adapter@​1.7.6
    • @​better-auth/mongo-adapter@​1.7.6
    • @​better-auth/telemetry@​1.7.6
Commits
  • 229a02a chore: release v1.7.6 (#11322)
  • dcaa5a7 feat(cli): add check command for schema validation (#11314)
  • fc45d08 fix(client): prevent stale query overwrites (#11376)
  • 8853419 fix: enforce maxPasswordLength before hashing on password verification endpoi...
  • 2fa501c fix(oauth-proxy): support social account linking (#11268)
  • 3d0efa3 feat(captcha): add Vercel BotID provider (#11016)
  • af88385 feat(admin): allow bannedUserMessage to be a function of the banned user (#11...
  • 2ee1545 fix(client): preserve auth query snapshots during hydration (#11316)
  • 0362d62 test(oauth): cover stateless implicit linking across instances (#11298)
  • See full diff in compare view

Updates bits-ui from 2.19.2 to 2.19.3

Release notes

Sourced from bits-ui's releases.

bits-ui@2.19.3

Patch Changes

  • Prevent delayed focus-scope autofocus from overriding focus already established in the scope or a nested scope. (#2165)

  • fix(Dialog, AlertDialog): pass preventOverflowTextSelection to the text selection layer explicitly instead of letting it ride the rest props onto the rendered content element as a preventoverflowtextselection attribute. (#2154)

  • fix(Floating): ignore autoUpdate callbacks that fire after the floating element's effect is destroyed to avoid derived_inert (#2164)

  • Fix user-select: none being stranded on <body> after clicking inside forceMounted content (Popover, Tooltip, Dialog, AlertDialog, Menu, Select), which left the whole page unselectable until a reload. (#2161)

  • refactor: the context-menu attribute names and the floating root/anchor state move to leaf modules, so DismissibleLayer no longer imports the menu module for two strings, and FloatingLayer / FloatingLayer.Anchor no longer import the floating content module (and @floating-ui/dom) to register a root and its trigger. No behaviour change. (#2158)

  • fix(Menu): the trigger's aria-controls links to the content when the menu starts open. The content registers its id by replacing a plain field on the menu state, which a trigger rendered before the content had already read as empty and never re-read; the registration is now reactive. (#2159)

  • fix(Combobox): open the trigger on a touch tap instead of on touch down, so a finger that lands on it while scrolling no longer opens the list. Takes the Select trigger's touch timing. (#2156)

  • perf: avoid O(n) work per rendered item on hot paths (#2110)

    • Select/Combobox: item props now derive from per-item booleans, so moving the highlight or changing the value only rebuilds props (and re-diffs attributes) for the items that actually changed instead of every mounted item
    • Select/Combobox (multiple): selection lookups use a set instead of scanning the value array once per item
    • Calendar/RangeCalendar: data-today resolves the local timezone once per calendar rather than once per cell
    • Menu family: the document-level pointermove listener is only attached while keyboard mode is active
    • ScrollArea, Slider, NavigationMenu: internal resize observation shares a single ResizeObserver across all observed elements
  • fix(TimeField): keep the day period when typing the hour and then editing another segment in 12-hour mode (#2148)

  • Fix user-select: none being left on <body> when something else on the page calls preventDefault() on a pointerup, which made the whole page unselectable. The text-selection layer's release is internal cleanup and no longer skipped when the event's default action has been cancelled. (#2163)

  • fix(Collapsible): invalidate deferred measurements when content is replaced or destroyed (#2149)

  • Fix outside clicks being lost while dismissible content such as DropdownMenu is opening. (#2143)

Commits
  • 4ece125 Version Packages (#2144)
  • 86d3875 test(ScrollArea): drive the resize-teardown test with a real resize (#2170)
  • e60291e fix(TimeField): keep the day period after typing the hour in 12-hour mode (#2...
  • c29acb2 refactor: leaf modules for the context-menu attribute names and the floating ...
  • cb111ef fix: invalidate deferred Collapsible measurements on cleanup (#2149)
  • fedf05f fix(Dialog, AlertDialog): pass preventOverflowTextSelection to the layer inst...
  • a2f53b9 fix(Combobox): open the trigger on a touch tap instead of on touch down (#2156)
  • 44e2ff7 fix(Menu): the trigger's aria-controls links to the content when the menu sta...
  • cc0a50e fix(TextSelectionLayer): release the held lock before arming a new one (#2161)
  • 3cffb10 fix(TextSelectionLayer): release the body lock even when pointerup is cance...
  • Additional commits viewable in compare view

Updates knip from 6.37.0 to 6.38.0

Release notes

Sourced from knip's releases.

Release 6.38.0

  • Include co-authors in docs contributor list (0c334100df59d89a512ad598ec50e7f62f6da0c3)
  • Filter bots and agents from docs contributors (617f70d8179c6b8668ca41fe5df77ced5e2b37c0)
  • Update Eve plugin conventions (#2049) (260dbb91a85f3a3bc2727e8f255d73df3737552c) - thanks @​matchai!
  • Add args example to that doc page (50b271b98fc930a05a3b045a2f691486f9f06528)
  • Add Turborepo plugin (#2055) (e49d3db05f1d69ce7db3efcb8467a4af63c27379) - thanks @​changbaebang!
  • Support import-x/* settings in ESLint plugin (#2050) (1a34cf82a3d6a1202717ef910bedba55838e9dd9) - thanks @​bytedoe!
  • Resolve file option in Mocha configuration files (#2051) (9b5c5f60468c8a92a3e74adca5c0931f008677af) - thanks @​giaBaoJS!
  • Support oxlint extends (#2054) (a149a98219bb14b15f446fc5f8c4f815e28b2183) - thanks @​matthewnitschke-wk!
  • Fix import.meta handling in built-in compilers (#2059) (8b0c85076bf3dce15ef5f3c0c4e58bfefdf59ded) - thanks @​vdavid!
  • Fix tag hints for enum and namespace members (#2061) (8a8805e48945863248429d18b7f6c4e4b7dc9ebd) - thanks @​devYRPauli!
  • Flag unused member tags in tagged enums and namespaces (584e53ff3e0846fbfe04fa5b5bfefe2420576a34)
  • feat: resolve MDX content mapper remarkPlugins (#2060) (34dbccf25359f9e9fefe9d0be6ef2ec0252223cc) - thanks @​gioboa!
  • Refactor and separate concerns w/ new typescript-content-mapper plugin (11e94509bd0f350d747facf4003fc5b248d1b02d)
  • Resolve mdx content mapper providerImportSource (7b5825117f97f2f87b7141509a254f88d0957cf7)
  • Fix config → entry in plop plugin (25a380c9e1165b76583d69b48b5fa7cdf5db0ae2)
Commits
  • c0e42f8 Release knip@6.38.0
  • 25a380c Fix config → entry in plop plugin
  • 7b58251 Resolve mdx content mapper providerImportSource
  • 11e9450 Refactor and separate concerns w/ new typescript-content-mapper plugin
  • 34dbccf feat: resolve MDX content mapper remarkPlugins (#2060)
  • 584e53f Flag unused member tags in tagged enums and namespaces
  • 8a8805e Fix tag hints for enum and namespace members (#2061)
  • 8b0c850 Fix import.meta handling in built-in compilers (#2059)
  • a149a98 Support oxlint extends (#2054)
  • 9b5c5f6 Resolve file option in Mocha configuration files (#2051)
  • Additional commits viewable in compare view

Updates @size-limit/preset-small-lib from 14.0.0 to 14.0.1

Release notes

Sourced from @​size-limit/preset-small-lib's releases.

14.0.1

  • Fixed increased size in rolldown plugin.
  • Fixed docs (by @​Likio3000).
Changelog

Sourced from @​size-limit/preset-small-lib's changelog.

14.0.1

  • Fixed increased size in rolldown plugin.
  • Fixed docs (by @​Likio3000).
Commits

Updates size-limit from 14.0.0 to 14.0.1

Release notes

Sourced from size-limit's releases.

14.0.1

  • Fixed increased size in rolldown plugin.
  • Fixed docs (by @​Likio3000).
Changelog

Sourced from size-limit's changelog.

14.0.1

  • Fixed increased size in rolldown plugin.
  • Fixed docs (by @​Likio3000).
Commits

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 28, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: pnpm. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

…updates

Bumps the minor-and-patch group with 6 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@lucide/svelte](https://github.com/lucide-icons/lucide/tree/HEAD/packages/svelte) | `1.47.0` | `1.48.0` |
| [better-auth](https://github.com/better-auth/better-auth/tree/HEAD/packages/better-auth) | `1.7.5` | `1.7.6` |
| [bits-ui](https://github.com/huntabyte/bits-ui) | `2.19.2` | `2.19.3` |
| [knip](https://github.com/webpro-nl/knip/tree/HEAD/packages/knip) | `6.37.0` | `6.38.0` |
| [@size-limit/preset-small-lib](https://github.com/ai/size-limit) | `14.0.0` | `14.0.1` |
| [size-limit](https://github.com/ai/size-limit) | `14.0.0` | `14.0.1` |



Updates `@lucide/svelte` from 1.47.0 to 1.48.0
- [Release notes](https://github.com/lucide-icons/lucide/releases)
- [Commits](https://github.com/lucide-icons/lucide/commits/1.48.0/packages/svelte)

Updates `better-auth` from 1.7.5 to 1.7.6
- [Release notes](https://github.com/better-auth/better-auth/releases)
- [Changelog](https://github.com/better-auth/better-auth/blob/main/packages/better-auth/CHANGELOG.md)
- [Commits](https://github.com/better-auth/better-auth/commits/v1.7.6/packages/better-auth)

Updates `bits-ui` from 2.19.2 to 2.19.3
- [Release notes](https://github.com/huntabyte/bits-ui/releases)
- [Commits](https://github.com/huntabyte/bits-ui/compare/bits-ui@2.19.2...bits-ui@2.19.3)

Updates `knip` from 6.37.0 to 6.38.0
- [Release notes](https://github.com/webpro-nl/knip/releases)
- [Commits](https://github.com/webpro-nl/knip/commits/knip@6.38.0/packages/knip)

Updates `@size-limit/preset-small-lib` from 14.0.0 to 14.0.1
- [Release notes](https://github.com/ai/size-limit/releases)
- [Changelog](https://github.com/ai/size-limit/blob/main/CHANGELOG.md)
- [Commits](ai/size-limit@14.0.0...14.0.1)

Updates `size-limit` from 14.0.0 to 14.0.1
- [Release notes](https://github.com/ai/size-limit/releases)
- [Changelog](https://github.com/ai/size-limit/blob/main/CHANGELOG.md)
- [Commits](ai/size-limit@14.0.0...14.0.1)

---
updated-dependencies:
- dependency-name: "@lucide/svelte"
  dependency-version: 1.48.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@size-limit/preset-small-lib"
  dependency-version: 14.0.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: better-auth
  dependency-version: 1.7.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: bits-ui
  dependency-version: 2.19.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: knip
  dependency-version: 6.38.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: size-limit
  dependency-version: 14.0.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title deps(deps): bump the minor-and-patch group with 6 updates deps(deps): bump the minor-and-patch group across 1 directory with 6 updates Sep 28, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/minor-and-patch-fef86e2dea branch from e1234eb to b5ec2b9 Compare September 28, 2026 21:32
@Divkix
Divkix merged commit fdac9c6 into main Sep 28, 2026
41 checks passed
@Divkix
Divkix deleted the dependabot/npm_and_yarn/minor-and-patch-fef86e2dea branch September 28, 2026 21:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant